Interscalar medicine / long-form research note / January 2025
Ethics of the Digital Patient
- The model is not the person
- Why build one?
- The representational gap
- Consent is a process, not a checkbox
- Privacy is more than secrecy
- Fairness begins before the model
- Transparency is layered
- Human oversight must be real
- Sustainability is a clinical design constraint
- Five practical scenarios
- From principles to an operating covenant
- Limits of the ethical claim
- Conclusion
The model is not the person
Medicine increasingly encounters a patient twice: once as a living person with a body, history, relationships, preferences, and the capacity to speak; and once as a computational object assembled from records, images, laboratory results, genomes, prescriptions, wearable sensors, messages, location traces, billing events, and predictions. This second object can help clinicians see change across time, compare plausible interventions, and coordinate care. It can also acquire an authority that its evidence does not justify.
In this article, a digital patient means a purpose-specific computational representation of a person that combines observed data with derived inferences and is used to describe, predict, simulate, or influence care. It is not a second person, a complete copy, or a neutral mirror. It is a model built by institutions, instruments, classifications, and choices.
Several related objects should not be confused:
- an electronic health record stores selected encounters and observations;
- a digital phenotype infers health or behavior from patterns in devices and digital activity;
- a risk model estimates a defined outcome for a defined population and time horizon;
- a health digital twin is a patient-specific virtual representation that is updated from multimodal patient, population, and environmental data and used to simulate states or interventions; and
- an avatar or interface visualizes information but may contain no causal or predictive model.
The literature itself uses these terms inconsistently. A useful minimum test for the word “twin” is therefore not visual resemblance but a declared clinical purpose, patient-specific calibration, an update mechanism, quantified uncertainty, and a demonstrated relationship between simulation and the physical patient. Reviews in npj Digital Medicine and Nature Computational Science describe the field as promising but still constrained by computation, implementation, governance, calibration, and evidence (Venkatesh et al., 2022, PMID 36138125; Laubenbacher et al., 2024, PMID 38532133).
A 2026 thematic review makes the maturity problem more explicit. Across 29 papers, Burr and colleagues identified 11 major ethical, legal, social, and implementation themes and a persistent gap between digital-twin promises and demonstrated capabilities. Their mapping to the NASSS implementation framework treats privacy, bias, governance, validation, human factors, interoperability, cybersecurity, and institutional capacity as determinants of adoption—not peripheral compliance work. The review also reports its own limits: technical databases and the search term “digital twin” may underrepresent legal, social, and adjacent biomedical-ethics scholarship (Burr et al., 2026, PMID 42254856). That combination of finding and caveat is important: the field should not confuse a growing ethics literature with a mature clinical evidence base.
Why build one?
A well-designed digital representation can serve legitimate and valuable ends.
First, it can preserve longitudinal continuity. A laboratory value, missed appointment, change in mobility, and medication refill may be unremarkable separately but meaningful as a sequence. Event-driven systems can help a care team notice deterioration earlier.
Second, it can support counterfactual reasoning. A calibrated mechanistic or statistical model may compare treatment options before exposing the patient to their costs and risks. Digital-twin research explores this possibility in oncology, cardiology, immune modeling, pharmacology, and critical care. The crucial word is may: a simulation is an argument based on assumptions, not a rehearsal of the future.
Third, it can strengthen patient agency. A comprehensible timeline, an account of which data affected a recommendation, and the ability to correct an error can make a fragmented system more navigable. A patient can be a participant in interpretation rather than merely a source of raw material.
Fourth, software can sometimes make decisions more auditable than unaided practice. Human judgment is not automatically fair, consistent, or explainable. A versioned model can be tested, its errors counted, and its use logged. Rejecting computation simply because it is computational would preserve the opacity and inequities already present in care.
These benefits are ethical reasons to investigate digital-patient systems. They are not ethical exemptions. The more closely a model is connected to treatment, triage, payment, or access, the stronger the evidence and safeguards it requires.
The representational gap
Every digital patient contains a gap between the person and the representation. Some facts are never measured. Other data are late, copied, miscoded, collected under unusual clinical pressure, or produced by devices whose accuracy varies by setting and user. Absence may mean “normal,” “not asked,” “could not afford the test,” “sensor was off,” or “care occurred elsewhere.” These meanings are not interchangeable.
The measurement layer can create inequity before an algorithm sees the data. In a prospective controlled study of 146 healthy volunteers and 9,763 paired measurements from two commonly used pulse oximeters, the combined frequency of missed hypoxaemia under low-perfusion conditions was 1.1% for light, 8.2% for medium, and 21.1% for dark skin pigmentation. The study used induced stable hypoxaemia in a laboratory, so those percentages should not be projected as prevalence in remote-care populations; they do show that pigmentation, perfusion, and physiological range can interact in the sensor itself (Gudelunas et al., 2024, PMID 38109495). A digital patient cannot repair a biased input merely by processing it more elegantly. Sensor validation across intended users and operating conditions belongs in the evidence plan.
The model then adds another layer: labels, proxies, thresholds, and objectives. A system asked to predict “need” may actually predict historical spending; a system asked to identify “adherence” may measure whether a pharmacy claim was filed; a system asked to infer mood from a phone may confuse distress with shift work, disability, travel, shared-device use, or deliberate disconnection.
This is not a hypothetical concern. Obermeyer and colleagues showed that a widely used population-health algorithm used health-care cost as a proxy for health need. Because less money had historically been spent on Black patients, equally scored Black patients were substantially sicker; replacing the proxy would have increased the proportion of Black patients receiving additional help from 17.7% to 46.5% (Science, 2019, PMID 31649194). The lesson is broader than race or one product: a technically accurate prediction can be ethically wrong when it predicts the wrong target.
The digital representation must therefore show its epistemic status. Observations, patient reports, clinician interpretations, administrative facts, model-derived inferences, and forecasts should not appear as if they were the same kind of truth. Each important output should carry its source, time, model version, intended use, uncertainty, and known limits. HL7 FHIR provides interoperable building blocks for consent, provenance, and audit events, but a standard can represent accountable practice only if an organization actually implements it (FHIR R5, Provenance, AuditEvent).
Consent is a process, not a checkbox
Digital-patient systems can join data collected for care with data from consumer devices, relatives, public records, or commercial brokers. They can also create new information that the patient never supplied: inferred pregnancy, cognitive decline, relapse risk, social isolation, or expected cost. Consent to a blood test is not self-evidently consent to train a commercial model; consent to a step counter is not self-evidently consent to infer mental state.
Valid authorization should be specific enough to distinguish at least:
- direct care from research, product development, payment, marketing, and public-health uses;
- data collection from model training, model inference, and onward disclosure;
- care-team access from access by vendors, insurers, employers, and other third parties;
- the current purpose from materially new purposes; and
- routine processing from decisions that could materially affect treatment or access.
More choice is not always more autonomy. A screen full of granular toggles can transfer governance work to a sick person and create consent fatigue. Emergency care, public-health duties, and some forms of quality improvement may also rely on legal bases other than consent. The ethical goal is not maximal clicking but meaningful control: short layered notices, stable defaults, a record of who used what and why, proportionate opportunities to opt out, and an accessible way to revise preferences. Dynamic-consent research suggests that ongoing communication and adjustable preferences can improve transparency, while also imposing technical and participation burdens (Spencer et al., 2016, PMID 27083521).
Consent burden can become digital treatment burden. A 2025 systematic review examined 148 technologies that were FDA-approved or vetted by the Organisation for the Review of Care and Health Apps and modeled a person living with five chronic conditions. Fewer than 5% addressed two or more conditions, and the hypothetical patient would need at least 15 technologies to obtain functions clinicians considered important (Phi et al., 2025, PMID 40279126). This was a modeled prescription, not a study of actual adherence or outcomes. Its ethical warning is nevertheless concrete: accounts, charging, calibration, alerts, data entry, troubleshooting, and contradictory instructions are patient and caregiver work. A digital patient can reduce that work by integrating care, or become one more layer that extracts it invisibly.
Consent also cannot solve collective harms. One person may authorize use of genomic, household, or neighborhood data that reveals information about relatives or groups. A representative dataset may require inclusion, while inclusion can expose communities to classification and stigma. These questions require institutional accountability and community participation, not a longer individual form.
The WHO Regional Office for Europe translates that institutional duty into four policy priorities: interoperable health-data standards, stronger national governance, coordination among data providers, and participation by patients, clinicians, and other stakeholders. It is a regional policy brief rather than binding law, but it usefully counters the idea that responsible AI can be built from individual consent plus a vendor contract alone (WHO/Europe, 2025, reference WHO/EURO:2025-11462-51234-78079).
In the European Union, the GDPR provides a concrete—though jurisdiction-specific—baseline: purpose limitation and data minimization, special protection for health data, rights of access and rectification, and safeguards around certain decisions based solely on automated processing. It does not create a simple universal “right to an explanation” for every clinical algorithm, and Article 22 has conditions and exceptions. The applicable legal basis, medical-device rules, research exemptions, national law, and role of each controller or processor must be assessed for the actual deployment (Regulation (EU) 2016/679, especially Articles 5, 9, 13–16, 20 and 22).
Privacy is more than secrecy
Privacy is often reduced to encryption or de-identification. Both are necessary and neither is sufficient. Longitudinal health records are distinctive; linkage with outside information may re-identify people; inferred attributes can be sensitive even when raw identifiers are absent; and a perfectly secure system can still be used for an unjustified purpose. A systematic review of demonstrated re-identification attacks also shows why risk must be assessed in context rather than treating “de-identified” as a permanent property of a dataset (El Emam et al., 2011, PMID 22164229).
Ethical privacy has at least four dimensions:
- Confidentiality: unauthorized parties cannot read the information.
- Purpose integrity: authorized parties cannot silently repurpose it.
- Power: patients are not forced to accept unnecessary surveillance to obtain ordinary care.
- Practical obscurity: the system does not make every intimate signal permanently searchable merely because storage is cheap.
Data minimization must apply to derived features and retention, not only to collection. “We might need it later” is not a clinical purpose. Systems should define retention periods, deletion and archival rules, model-training lineage, breach response, and what happens to a patient-specific model when a patient changes provider or withdraws from an optional service. Privacy-enhancing technologies—federated learning, secure computation, differential privacy, and synthetic data—may reduce exposure, but each creates tradeoffs in accuracy, bias, auditability, or operational complexity. They are controls to evaluate, not magic words.
Information security still needs a health-specific control system. ISO 27799:2025 applies ISO/IEC 27002-based controls to organizations responsible for health information, including electronic records, health software, medical devices, cloud processing, and remote or virtual care (official catalogue). It helps organize confidentiality, integrity, availability, and operational controls. Like every security standard, however, it cannot decide whether a proposed inference, recipient, or purpose is ethically justified.
Fairness begins before the model
Bias enters through access to care, device ownership, measurement, coding, missingness, target selection, annotation, deployment, and the response to an alert. It cannot be repaired by one fairness metric at the end.
A system trained on patients who own current smartphones may underrepresent older, poorer, rural, disabled, institutionalized, or intermittently connected people. A wearable that is removed during manual work can interpret employment as nonadherence. A risk score can be equally calibrated across groups yet still distribute false negatives in a clinically unacceptable way. Different fairness criteria can conflict; the appropriate criterion depends on the harm, the use, and the affected population.
Responsible evaluation should therefore report performance, calibration, missingness, and error consequences across clinically and socially relevant subgroups; examine intersectional groups where sample size permits; and involve people who will bear false positives, false negatives, and surveillance. The evaluation population must match the intended-use population. Dataset shift—differences between development data and later clinical environments—can break an apparently strong biomarker, which is why external validation and continuing monitoring are ethical requirements rather than optional statistical refinements (Dockès et al., 2021, PMID 34585237).
There is also a genuine counterargument: withholding a beneficial system until it performs identically for every group can itself cause avoidable harm. Selective or staged deployment may sometimes be defensible when benefits are well demonstrated for a defined population, exclusions are explicit rather than hidden, conventional care remains available, and there is a funded plan to close the evidence gap. “Incomplete equity” cannot become a permanent excuse, but neither should fairness be interpreted as a demand to deny proven benefit to everyone.
Transparency is layered
“Explain the algorithm” can refer to several different obligations:
- system transparency: who built, owns, bought, and governs it;
- data transparency: what data and labels were used, from which populations, and under what exclusions;
- performance transparency: where it was validated, for whom, against what comparator, and with what failures;
- case-level intelligibility: what the output means for this patient, which inputs materially influenced it, and how uncertain it is;
- procedural transparency: who saw the output, what action followed, and how a person can challenge it.
No single heat map or feature-attribution chart satisfies all five. Post-hoc explanations can be unstable or persuasive without being faithful to the model. Ghassemi, Oakden-Rayner, and Beam warn that current explainability methods can provide false reassurance and should not substitute for rigorous validation (Lancet Digital Health, 2021, PMID 34711379).
Full source-code disclosure is also neither always possible nor sufficient. Proprietary rights, security, and model complexity may limit publication, while open code can remain unintelligible to a patient and unsafe in a new setting. The practical standard should be contestable transparency: enough accessible and independently verifiable information for patients, clinicians, procurers, auditors, and regulators to perform their distinct roles. A patient needs the consequence and route to correction; a clinician needs intended use, uncertainty, and alternatives; an auditor needs data lineage, versioning, subgroup results, logs, and access to technical evidence.
Human oversight must be real
“A human is in the loop” is not a safety property. A clinician who lacks time, authority, information, or a workable alternative may merely ratify the machine. Conversely, requiring a human to approve every low-risk output can create alert fatigue and diffuse responsibility.
Automation bias—the tendency to over-rely on automated advice—has been documented across decision tasks and is aggravated by workload, complexity, and difficult verification (Goddard et al., 2012, PMID 21685142; Lyell & Coiera, 2017, PMID 27516495). Oversight should therefore be designed around the consequence of error:
Empirical evidence shows why an explanation cannot be treated as a backstop by itself. In a randomized vignette study involving 457 hospital clinicians, standard AI predictions raised diagnostic accuracy by 2.9 percentage points over baseline, or 4.4 points when accompanied by image-based explanations. Systematically biased predictions instead reduced accuracy by 11.3 points; explanations did not significantly mitigate that harm, with accuracy still 9.1 points below baseline. This was a simulated acute-respiratory-failure task, not a trial of live patient outcomes, and it tested one class of explanation. Even with those limits, it demonstrates that a plausible visual explanation and the presence of a clinician do not establish safe joint performance (Jabbour et al., 2023, PMID 38112814; ClinicalTrials.gov NCT06098950).
- the reviewer knows the system’s intended use and failure modes;
- the interface displays uncertainty and missing inputs rather than a naked score;
- the reviewer can inspect relevant source data and seek an independent view;
- disagreement is safe to record and does not require gaming the workflow;
- urgent escalation and system shutdown are possible; and
- overrides, non-use, and downstream outcomes are monitored without automatically treating clinician disagreement as error.
Responsibility is distributed but must not be diluted. Developers are responsible for design claims, data practices, testing, version control, and disclosed limitations. Health organizations are responsible for procurement, local validation, workflow, training, security, monitoring, and incident response. Clinicians remain responsible for professional use within the authority and evidence they actually possess. Regulators and payers shape incentives and minimum evidence. Patients may contribute preferences and correct data, but they are not responsible for detecting defects in a system imposed on their care.
The EU AI Act illustrates the move toward lifecycle obligations for high-risk AI, including risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, and post-market monitoring. Some AI systems that are medical devices or safety components and require third-party conformity assessment fall within the high-risk regime; classification depends on intended purpose and the applicable product law, not on the marketing use of the word “AI” (Regulation (EU) 2024/1689, Article 6 and Annex I; MDCG 2025-6).
Sustainability is a clinical design constraint
A continuously updated digital patient consumes more than compute. It may require sensors and replacements, network traffic, long-term storage, redundant data pipelines, model training and inference, cybersecurity, specialist staff, and institutional attention. Those resources have energy, material, financial, and opportunity costs. In a resource-constrained service, capacity devoted to a technically elaborate twin can displace simpler monitoring, staffing, or access interventions that produce more health.
The opposite claim also deserves a fair hearing. A useful model may avoid travel, duplicative imaging, failed treatments, admissions, or waste. “Digital” is not inherently less sustainable, and a large model is not inherently unjustified. The ethical requirement is a comparative lifecycle account: measure the incremental clinical value and the incremental burden against realistic alternatives, including who receives the benefit and who bears infrastructure costs.
A 2026 prospective case study shows why operational and embodied impacts both matter. In a lifecycle assessment of an e-referral service at a major Paris hospital, servers dominated the service’s footprint across the modeled utilization scenarios, while production of computing hardware accounted for 45% of the carbon footprint and most metallic-resource depletion. The study concerns one referral service, not a patient twin, and does not establish a portable coefficient for other architectures. It does demonstrate the kind of prospective inventory—usage, servers, networks, terminals, hardware production, and comparison with an alternative—that a serious sustainability claim requires (Morand et al., 2026, PMID 42315963).
A September 2025 briefing note from the Ethics Unit of the French Ministry of Health’s Digital Health Delegation makes environmental responsibility part of digital-twin ethics and warns that costly, energy-intensive infrastructure can deepen unequal access. It is a multidisciplinary policy note, not a peer-reviewed lifecycle assessment, so it identifies a governance question rather than quantifying a universal footprint (Digital Twins in Health: Issues, Definitions and Ethical Challenges). Procurement should therefore specify update frequency, retention, device lifespan and repair, energy and cloud dependencies, carbon/material reporting where measurable, service continuity, and a proportionality test: could a smaller and simpler system deliver comparable patient benefit?
Five practical scenarios
1. Remote monitoring after discharge
A heart-failure service combines weight, heart rate, symptoms, medication events, and missed measurements to prioritize calls. The benefit is earlier attention without asking every patient to travel. The risks include sensor error, broadband exclusion, surveillance inside the home, and a queue that mistakes missing data for stability.
Minimum safeguards: a non-digital pathway; clear hours and response times; a statement that the system is not an emergency service; monitoring of missingness as a safety signal; device support; patient-visible corrections; measurement of patient and caregiver workload; limits on the number of accounts, devices, and duplicate alerts; and periodic comparison of outcomes across access, disability, age, sex, language, ethnicity, and socioeconomic groups.
2. A predictive deterioration alert
An event-driven model detects a pattern that precedes sepsis or readmission. A high sensitivity may save lives but can generate false alarms; a high specificity may miss uncommon presentations. The ethical unit is not the model’s area under a curve but the entire sociotechnical pathway: who receives the alert, what they can do, what care is displaced, and whether benefit reaches the patient.
Minimum safeguards: prospective silent testing before activation; predefined escalation and abstention rules; measurement of time-to-action, adverse events, alert burden, overrides, and patient outcomes; local and subgroup validation; drift monitoring; and an accountable owner with authority to pause the system.
3. A treatment-simulation twin
A cancer or cardiac model compares plausible interventions for one patient. This can organize complex evidence and reduce trial-and-error. But a simulated counterfactual is especially easy to anthropomorphize: “the twin responded” may conceal that the result depends on population data, causal assumptions, and parameters not observed in this person.
Minimum safeguards: show the range of plausible outcomes and assumptions; distinguish prediction from causal evidence; compare with standard care and multidisciplinary judgment; identify out-of-distribution cases; never present a simulated benefit as an observed patient outcome; and require prospective clinical evidence before autonomous treatment control.
4. Digital phenotyping in mental health
A phone uses sleep, movement, typing, voice, or communication patterns to estimate relapse risk. Passive signals may reveal change between appointments, including when a person cannot articulate it. The same system can create continuous behavioral surveillance, draw intimate inferences about bystanders, pathologize ordinary variation, or overrule a patient’s first-person account. Ethical analysis of digital phenotyping highlights privacy, consent, bias, accountability, and the risk of epistemic injustice (Martinez-Martin et al., 2021, PMID 34319252; Slack & Barclay, 2023, PMID 37725254).
Minimum safeguards: opt-in use where feasible; granular sensor permissions; on-device processing where appropriate; prohibition of unrelated policing, employment, or advertising uses; a human response capacity proportionate to the promise of monitoring; and a rule that a model’s inference invites conversation rather than invalidates testimony.
5. Secondary use by research, insurers, or employers
Aggregated digital-patient data can improve research and reveal service inequities. It can also support risk segmentation, pricing, exclusion, or productivity surveillance. A use that benefits a population may burden identifiable groups even if no individual’s name is exposed.
Minimum safeguards: a documented lawful basis and public-interest rationale; independent review; purpose and recipient controls; contractual bans on adverse non-clinical use; privacy and re-identification assessment; community representation; publication of significant findings and incidents; and a route for collective as well as individual redress.
From principles to an operating covenant
A deployable ethics policy should answer concrete questions before the first patient is enrolled or scored.
- Purpose: What exact clinical or operational decision will the system support, for whom, in what setting, and what will it never be used for?
- Evidence: What comparator, outcomes, external validation, prospective evaluation, and subgroup analyses support that use?
- Representation: Which inputs are observed, reported, inferred, simulated, or missing? How are source, time, and uncertainty shown?
- Necessity: Is every collected and derived variable necessary and proportionate to the purpose?
- Choice: What notice, consent or other lawful basis applies? Is equivalent care available without optional monitoring?
- Access: Who can read, change, export, train on, or disclose the representation, and can each action be audited?
- Correction: Can a patient and clinician correct source data and challenge an inference without erasing the historical audit trail?
- Human authority: Who can question, override, pause, or retire the system, and do they have the time and competence to do so?
- Failure: What happens when data are missing, the model abstains, the network fails, a vendor closes, or a cyberattack occurs?
- Monitoring: Which clinical, technical, equity, workload, and patient-experience outcomes are monitored after deployment, and what thresholds trigger investigation or shutdown?
- Change: How are new data, retraining, model updates, interface changes, and changed intended uses validated, communicated, and versioned?
- Redress and exit: How can a person obtain an explanation appropriate to the consequence, request human review, appeal harm, export relevant information, and leave an optional service?
- Sustainability and proportionality: What energy, material, workforce, and opportunity costs arise across the lifecycle, who bears them, and could a smaller system deliver comparable benefit?
These questions align with lifecycle approaches in the WHO guidance on AI for health, NIST AI RMF, medical-device risk management, secure software lifecycle standards, and international good machine-learning practice. They do not collapse into one certification. Relevant references include the WHO guidance (ISBN 978-92-4-002920-0), NIST AI RMF 1.0, ISO 14971:2019, IEC 62304:2006+A1:2015, IEC 81001-5-1:2021, ISO/IEC 23894:2023, ISO/IEC 42001:2023, ISO 27799:2025, ISO/TS 82304-2:2021, and IMDRF/AIML WG/N88 FINAL:2025.
One way to keep such claims from becoming a checklist ritual is an assurance case: a structured argument connecting a declared property—such as safety, fairness, or explainability—to evidence, assumptions, rebuttals, owners, and review. An Alan Turing Institute project report describes a participatory, argument-based Trustworthy and Ethical Assurance platform for digital twins (Burr et al., 2024). It is a non-peer-reviewed implementation report and not proof of clinical benefit; its practical contribution is to make the justification inspectable and revisable rather than merely asserted.
Clinical evidence also needs transparent reporting. CONSORT-AI asks trials to specify intended use, users, integration into the clinical pathway, input handling, outputs, human–AI interaction, version changes, and error analysis (Liu et al., 2020, PMID 32908283). DECIDE-AI addresses early live clinical evaluation and human factors (Vasey et al., 2022, PMID 35585198). TRIPOD+AI updates reporting for prediction models (Collins et al., 2024, PMID 38626948). Reporting guidance improves inspectability; it does not by itself prove benefit.
Limits of the ethical claim
The principle “augment the physician, do not replace judgment” is directionally sound but incomplete.
Some bounded automated functions may be safer than mandatory human review. A human can introduce delay, inconsistency, prejudice, or error. Conversely, a nominal human checkpoint can legitimize an unsafe recommendation. The right question is not whether a human touched the output but whether the combined human–technology system produces better, fairer, contestable outcomes for the intended patients.
The evidence base is also uneven. Much of the digital-twin literature remains conceptual, technical, or retrospective; a review, consensus process, controlled sensor experiment, or vignette study can reveal risks without demonstrating routine clinical benefit. Ethical assurance therefore has to be paired with prospective outcome evaluation and the institutional capability to stop, repair, or retire a system.
Not every digital-patient system is a medical device, not every model uses AI, and not every ethical obligation is a legal right. Regulation varies by jurisdiction and intended use. Published prototypes, consensus statements, standards, regulatory clearance, and patents are different forms of evidence. None should be mistaken for proof that a product improves patient outcomes in routine care.
Most importantly, no model can exhaust the person it represents. A patient can revise a goal, refuse an optimization, explain an apparent anomaly, or value an outcome the training data did not encode. Ethical digital medicine begins when this surplus of person over profile is treated not as noise, but as the reason the system exists.
Conclusion
A digital patient should be a revisable clinical instrument, never an administrative destiny. It should make uncertainty visible, keep facts separate from inferences, preserve meaningful alternatives, and leave a traceable path from data to action. Its benefits should be demonstrated in the populations and workflows where it is used; its errors should be measurable; its owners and operators should be answerable; and the person represented should be able to understand the consequence, correct the record, contest the decision, and leave optional surveillance.
The governing rule is therefore stronger than “keep a doctor in the loop”: the digital representation must remain subordinate to the rights, testimony, welfare, and changing purposes of the person.
Интерскалярная медицина / полноформатная исследовательская статья / январь 2025
Этика цифрового пациента
- Модель — не человек
- Зачем его создавать?
- Разрыв между человеком и представлением
- Согласие — процесс, а не галочка
- Приватность — больше, чем тайна
- Справедливость начинается до обучения модели
- Прозрачность имеет слои
- Человеческий контроль должен быть реальным
- Устойчивость — требование к клиническому проектированию
- Пять практических сценариев
- От принципов к рабочему договору
- Ограничения этического тезиса
- Вывод
Модель — не человек
Современная медицина всё чаще встречает пациента дважды: как живого человека с телом, биографией, отношениями, предпочтениями и способностью говорить за себя — и как вычислительный объект, собранный из медицинских записей, изображений, лабораторных результатов, геномных данных, назначений, сигналов носимых устройств, сообщений, геолокации, платёжных событий и прогнозов. Второй объект помогает увидеть динамику, сопоставить возможные вмешательства и координировать помощь. Но он же может приобрести авторитет, которого не заслуживает его доказательная база.
В этой статье цифровой пациент — это целевое вычислительное представление человека, объединяющее наблюдаемые данные и производные выводы и используемое для описания, прогнозирования, моделирования или изменения медицинской помощи. Это не второй человек, не полная копия и не нейтральное зеркало. Это модель, созданная институтами, приборами, классификациями и человеческими решениями.
Важно различать близкие, но не тождественные объекты:
- электронная медицинская карта хранит выбранные встречи и наблюдения;
- цифровой фенотип выводит сведения о здоровье или поведении из паттернов устройств и цифровой активности;
- модель риска оценивает определённый исход для определённой популяции и временного горизонта;
- медицинский цифровой двойник — индивидуализированное виртуальное представление, обновляемое мультимодальными данными пациента, популяционными и средовыми данными и применяемое для моделирования состояний или вмешательств;
- аватар или интерфейс визуализирует сведения, но может не содержать ни причинной, ни прогностической модели.
В научной литературе эти термины также используются непоследовательно. Поэтому минимальный критерий слова «двойник» — не визуальное сходство, а объявленная клиническая цель, индивидуальная калибровка, механизм обновления, количественно выраженная неопределённость и доказанная связь между симуляцией и физическим пациентом. Обзоры в npj Digital Medicine и Nature Computational Science описывают направление как перспективное, но всё ещё ограниченное вычислительными требованиями, внедрением, управлением данными, калибровкой и качеством доказательств (Venkatesh et al., 2022, PMID 36138125; Laubenbacher et al., 2024, PMID 38532133).
Тематический обзор 2026 года делает проблему зрелости ещё яснее. В 29 работах Burr и соавторы выделили 11 крупных этических, правовых, социальных и внедренческих тем и устойчивый разрыв между обещаниями цифровых двойников и доказанными возможностями. Сопоставление с моделью внедрения NASSS показывает, что приватность, смещение, управление, валидация, человеческие факторы, совместимость, кибербезопасность и институциональная готовность определяют саму возможность внедрения, а не являются периферийной «проверкой соответствия». Авторы прямо называют ограничения обзора: технические базы и поисковый термин digital twin могли недопредставить правовую, социальную и смежную биоэтическую литературу (Burr et al., 2026, PMID 42254856). Это сочетание вывода и оговорки принципиально: растущую литературу об этике нельзя принимать за зрелую клиническую доказательную базу.
Зачем его создавать?
У качественного цифрового представления есть законные и ценные задачи.
Во-первых, оно поддерживает непрерывность во времени. Лабораторный показатель, пропущенный визит, изменение подвижности и задержка получения лекарства по отдельности могут быть незначимы, но оказаться важными как последовательность событий. Событийная система способна раньше привлечь внимание команды к ухудшению состояния.
Во-вторых, оно поддерживает контрфактическое рассуждение. Калиброванная механистическая или статистическая модель может сопоставить варианты лечения до того, как пациент столкнётся с их рисками и затратами. Цифровые двойники исследуются в онкологии, кардиологии, иммунологии, фармакологии и интенсивной терапии. Ключевое слово здесь — «может»: симуляция является аргументом, построенным на предпосылках, а не репетицией будущего.
В-третьих, цифровое представление может усиливать субъектность пациента. Понятная временная линия, указание на данные, повлиявшие на рекомендацию, и возможность исправить ошибку делают фрагментированную систему более управляемой. Пациент становится участником интерпретации, а не только источником сырья.
В-четвёртых, программная система иногда делает решения более проверяемыми, чем помощь без цифровой поддержки. Человеческое суждение не является автоматически справедливым, последовательным или объяснимым. Версионируемую модель можно тестировать, её ошибки — считать, а использование — журналировать. Отказ от вычислительного инструмента только из-за его вычислительной природы законсервировал бы непрозрачность и неравенство обычной практики.
Это этические основания исследовать системы цифрового пациента, но не освобождение от этики. Чем теснее модель связана с лечением, сортировкой, оплатой или доступом к помощи, тем сильнее должны быть доказательства и защитные меры.
Разрыв между человеком и представлением
В любом цифровом пациенте остаётся разрыв между человеком и моделью. Часть фактов никогда не измеряется. Другие данные запаздывают, копируются с ошибкой, неверно кодируются, собираются в условиях клинического стресса или поступают с устройств, точность которых зависит от среды и пользователя. Отсутствие значения может означать «норма», «не спрашивали», «пациент не мог оплатить исследование», «датчик был снят» или «помощь получена в другом месте». Эти значения неравнозначны.
Неравенство может возникнуть на измерительном слое ещё до обработки алгоритмом. В проспективном контролируемом исследовании 146 здоровых добровольцев и 9 763 парных измерений двух распространённых пульсоксиметров суммарная частота пропуска гипоксемии при низкой перфузии составила 1,1% для светлой, 8,2% для средней и 21,1% для тёмной пигментации кожи. Исследование проводилось при индуцированной стабильной гипоксемии в лаборатории, поэтому эти проценты нельзя переносить как распространённость на популяции дистанционного наблюдения; они показывают взаимодействие пигментации, перфузии и физиологического диапазона в самом датчике (Gudelunas et al., 2024, PMID 38109495). Цифровой пациент не исправляет смещённый вход лишь за счёт более изящной обработки. Проверка датчиков на целевых пользователях и в условиях назначения должна входить в план доказательств.
Затем модель добавляет новый слой: метки, прокси-показатели, пороги и целевые функции. Система, которой поручено предсказывать «потребность», может на деле предсказывать исторические расходы; «приверженность» — наличие аптечного требования; настроение по телефону — спутать дистресс со сменной работой, инвалидностью, поездкой, общим устройством или сознательным отключением.
Это не гипотетическая проблема. Obermeyer и соавторы показали, что широко применявшийся алгоритм управления здоровьем популяций использовал расходы на помощь как прокси медицинской потребности. Поскольку исторически на помощь чернокожим пациентам тратили меньше, при одинаковом балле они были существенно тяжелее; замена прокси увеличила бы долю чернокожих пациентов, получающих дополнительную помощь, с 17,7% до 46,5% (Science, 2019, PMID 31649194). Урок шире одного продукта: технически точный прогноз может быть этически неверным, если предсказывает не ту цель.
Поэтому цифровое представление должно показывать эпистемический статус каждого элемента. Наблюдения, слова пациента, интерпретации врача, административные факты, модельные выводы и прогнозы не должны выглядеть одинаково истинными. Для значимого вывода нужны источник, время, версия модели, назначение, неопределённость и известные ограничения. HL7 FHIR предлагает совместимые структуры для согласия, происхождения данных и аудита событий, но стандарт описывает подотчётность лишь тогда, когда организация действительно реализует соответствующую практику (FHIR R5, Provenance, AuditEvent).
Согласие — процесс, а не галочка
Система цифрового пациента способна объединять данные, собранные для лечения, с данными потребительских устройств, родственников, открытых реестров или коммерческих брокеров. Она создаёт и сведения, которых пациент не сообщал: предполагаемую беременность, когнитивное снижение, риск рецидива, социальную изоляцию или ожидаемую стоимость помощи. Согласие на анализ крови не означает автоматически согласие на обучение коммерческой модели; согласие на счётчик шагов — на вывод о психическом состоянии.
Действительное разрешение должно как минимум различать:
- непосредственное лечение и исследования, разработку продукта, оплату, маркетинг и общественное здравоохранение;
- сбор данных, обучение модели, выполнение вывода и последующую передачу;
- доступ лечащей команды и доступ поставщиков, страховщиков, работодателей и иных третьих лиц;
- текущую цель и существенно новую цель;
- обычную обработку и решения, способные заметно повлиять на лечение или доступ к нему.
Больше переключателей не всегда означает больше автономии. Экран с десятками настроек может переложить работу по управлению системой на больного человека и вызвать усталость от согласий. Экстренная помощь, обязанности общественного здравоохранения и некоторые виды повышения качества могут опираться на иное правовое основание. Этическая цель — не максимум кликов, а осмысленный контроль: краткие многоуровневые уведомления, устойчивые настройки по умолчанию, запись о том, кто, что и зачем использовал, соразмерная возможность отказа и доступное изменение предпочтений. Исследования динамического согласия показывают потенциал постоянной коммуникации и изменяемых настроек, но также выявляют техническую нагрузку и барьеры участия (Spencer et al., 2016, PMID 27083521).
К нагрузке согласия добавляется цифровая лечебная нагрузка. Систематический обзор 2025 года исследовал 148 технологий, одобренных FDA или проверенных Organisation for the Review of Care and Health Apps, и смоделировал ситуацию человека с пятью хроническими заболеваниями. Менее 5% технологий охватывали два или более состояния, а гипотетическому пациенту потребовалось бы не менее 15 технологий, чтобы получить функции, которые клиницисты сочли важными (Phi et al., 2025, PMID 40279126). Это модель назначения, а не исследование реальной приверженности или исходов. Но этическое предупреждение конкретно: учётные записи, зарядка, калибровка, уведомления, ввод данных, устранение сбоев и противоречивые инструкции являются трудом пациента и близких. Цифровой пациент способен уменьшить этот труд за счёт интеграции — или стать ещё одним слоем, который незаметно его извлекает.
Согласие не решает коллективные риски. Один человек может разрешить использование геномных, семейных или районных данных, раскрывающих сведения о родственниках и группах. Репрезентативный набор требует включения, но само включение способно привести к стигматизирующей классификации сообщества. Здесь нужны институциональная ответственность и участие сообществ, а не более длинная индивидуальная форма.
Европейское региональное бюро ВОЗ переводит эту институциональную обязанность в четыре приоритета политики: совместимые стандарты медицинских данных, усиление национального управления, координацию поставщиков данных и участие пациентов, медицинских работников и других заинтересованных сторон. Это региональная аналитическая записка, а не обязательный закон, но она полезно опровергает представление, будто для ответственного ИИ достаточно индивидуального согласия и договора с поставщиком (WHO/Europe, 2025, номер WHO/EURO:2025-11462-51234-78079).
В Европейском союзе GDPR задаёт конкретную, хотя и юрисдикционно ограниченную основу: ограничение цели и минимизацию данных, особую защиту данных о здоровье, права доступа и исправления, а также гарантии в отношении некоторых решений, основанных исключительно на автоматизированной обработке. Регламент не создаёт простого универсального «права на объяснение» для любого медицинского алгоритма; у статьи 22 есть условия и исключения. Для конкретного внедрения необходимо определить правовое основание, применимость правил медицинских изделий и исследований, национальное законодательство и роли контролёров и обработчиков (Регламент (ЕС) 2016/679, особенно статьи 5, 9, 13–16, 20 и 22).
Приватность — больше, чем тайна
Приватность часто сводят к шифрованию или деидентификации. Оба средства необходимы, но недостаточны. Продольные медицинские истории уникальны; связывание с внешними данными может повторно идентифицировать человека; производные признаки бывают чувствительными даже без прямых идентификаторов; а идеально защищённая система всё равно может использоваться для неоправданной цели. Систематический обзор продемонстрированных атак повторной идентификации также показывает, почему риск нужно оценивать в контексте, а не считать «деидентифицированность» постоянным свойством набора данных (El Emam et al., 2011, PMID 22164229).
У этической приватности есть по меньшей мере четыре измерения:
- Конфиденциальность: посторонние не могут прочитать информацию.
- Целостность цели: уполномоченные лица не могут незаметно изменить назначение данных.
- Распределение власти: пациента не вынуждают принимать ненужное наблюдение ради обычной помощи.
- Практическая несводимость к поиску: интимный сигнал не становится навсегда доступным для поиска лишь потому, что хранение дёшево.
Минимизация должна относиться не только к сбору, но и к производным признакам и срокам хранения. Фраза «вдруг пригодится» не является клинической целью. Нужны сроки, правила удаления и архива, происхождение обучающих данных, план реагирования на утечку и решение о судьбе персональной модели при смене клиники или выходе из необязательной программы. Федеративное обучение, защищённые вычисления, дифференциальная приватность и синтетические данные могут снижать раскрытие, но создают компромиссы точности, справедливости, проверяемости и сложности. Это меры контроля, требующие оценки, а не магические слова.
Информационной безопасности всё равно нужна система мер, учитывающая специфику здравоохранения. ISO 27799:2025 применяет основанные на ISO/IEC 27002 меры к организациям, отвечающим за медицинскую информацию, включая электронные карты, медицинское ПО, медицинские изделия, облачную обработку и дистанционную или виртуальную помощь (официальный каталог). Стандарт помогает организовать конфиденциальность, целостность, доступность и операционные меры. Но, как и любой стандарт безопасности, он не решает, оправданы ли этически конкретный вывод, получатель или цель.
Справедливость начинается до обучения модели
Смещение входит в систему через доступ к помощи, владение устройствами, измерение, кодирование, пропуски, выбор целевой переменной, разметку, внедрение и реакцию на предупреждение. Его нельзя исправить одной метрикой справедливости в конце.
Система, обученная на владельцах современных смартфонов, может недопредставлять пожилых, малообеспеченных, сельских жителей, людей с инвалидностью, проживающих в учреждениях или имеющих нестабильную связь. Носимое устройство, снятое во время ручной работы, способно принять занятость за неприверженность. Одинаково калиброванный по группам балл может всё равно давать клинически неприемлемое распределение ложноотрицательных ошибок. Метрики справедливости конфликтуют; выбор зависит от вреда, сценария и затронутой популяции.
Поэтому ответственная оценка должна публиковать качество, калибровку, пропуски и последствия ошибок для клинически и социально значимых подгрупп; при достаточном размере — изучать их пересечения; привлекать людей, которые столкнутся с ложными тревогами, пропусками и наблюдением. Популяция оценки должна соответствовать популяции назначения. Сдвиг данных — отличие среды разработки от реальной практики — способен разрушить сильный на исходной выборке биомаркер; поэтому внешняя валидация и постоянный мониторинг являются этической обязанностью, а не факультативной статистической доработкой (Dockès et al., 2021, PMID 34585237).
Есть и серьёзный контраргумент: отказ от полезной системы до достижения одинакового качества для всех групп сам может причинить предотвратимый вред. Выборочное или поэтапное внедрение иногда допустимо, если польза убедительно показана для определённой популяции, исключения объявлены, а не скрыты, обычная помощь остаётся доступной и существует финансируемый план закрытия пробела в доказательствах. «Неполная справедливость» не должна становиться постоянным оправданием, но и справедливость не должна означать отказ всем в доказанной пользе.
Прозрачность имеет слои
Требование «объяснить алгоритм» может обозначать разные обязанности:
- прозрачность системы: кто её создал, кому она принадлежит, кто закупил и кто управляет;
- прозрачность данных: какие данные и метки использовались, из каких популяций и с какими исключениями;
- прозрачность качества: где, для кого, против какого сравнения и с какими ошибками система проверялась;
- понятность конкретного случая: что вывод означает для этого пациента, какие входы существенно повлияли и какова неопределённость;
- процедурная прозрачность: кто увидел вывод, какое действие последовало и как его оспорить.
Ни тепловая карта, ни диаграмма важности признаков не закрывают все пять слоёв. Постфактум-объяснения могут быть нестабильными или убедительными, не будучи верными модели. Ghassemi, Oakden-Rayner и Beam предупреждают, что современные методы объяснимости способны создавать ложную уверенность и не должны заменять строгую валидацию (Lancet Digital Health, 2021, PMID 34711379).
Полное раскрытие исходного кода также не всегда возможно и само по себе недостаточно. Права на интеллектуальную собственность, безопасность и сложность ограничивают публикацию; открытый код может остаться непонятным пациенту и небезопасным в новой среде. Практический стандарт — проверяемая и оспоримая прозрачность: достаточно доступной и независимо проверяемой информации, чтобы пациент, врач, закупщик, аудитор и регулятор исполнили разные роли. Пациенту нужны последствия и путь исправления; врачу — назначение, неопределённость и альтернативы; аудитору — происхождение данных, версии, результаты по подгруппам, журналы и технические доказательства.
Человеческий контроль должен быть реальным
Фраза «человек остаётся в контуре» не является свойством безопасности. Врач без времени, полномочий, информации или доступной альтернативы лишь утверждает машинный вывод. Но обязательное ручное подтверждение каждого малорискового действия также создаёт усталость от предупреждений и размывает ответственность.
Склонность чрезмерно полагаться на автоматическую рекомендацию — automation bias — показана в разных задачах и усиливается при высокой нагрузке, сложности и трудной проверке (Goddard et al., 2012, PMID 21685142; Lyell & Coiera, 2017, PMID 27516495). Поэтому контроль должен соответствовать последствиям ошибки:
Эмпирические данные показывают, почему объяснение само по себе нельзя считать страховочной сеткой. В рандомизированном исследовании виньеток с участием 457 госпитальных клиницистов обычные прогнозы ИИ повысили диагностическую точность относительно исходного уровня на 2,9 процентного пункта, а с визуальными объяснениями — на 4,4 пункта. Систематически смещённые прогнозы, напротив, снизили точность на 11,3 пункта; объяснения не уменьшили вред статистически значимо, и точность всё равно оставалась на 9,1 пункта ниже исходной. Это была симуляция случаев острой дыхательной недостаточности, а не исследование реальных исходов, и проверялся один класс объяснений. Но даже с этими ограничениями работа показывает: убедительная визуализация и присутствие врача не доказывают безопасность совместной работы (Jabbour et al., 2023, PMID 38112814; ClinicalTrials.gov NCT06098950).
- проверяющий знает назначение системы и типичные отказы;
- интерфейс показывает неопределённость и отсутствующие входы, а не голый балл;
- можно увидеть релевантные первичные данные и запросить независимое мнение;
- несогласие безопасно фиксируется и не требует обхода процесса;
- возможны срочная эскалация и остановка системы;
- переопределения, неиспользование и последующие исходы анализируются без автоматического признания несогласия врача ошибкой.
Ответственность распределена, но не должна растворяться. Разработчик отвечает за заявленное назначение, работу с данными, тестирование, версии и раскрытие ограничений. Медицинская организация — за закупку, локальную валидацию, процесс, обучение, безопасность, мониторинг и инциденты. Врач — за профессиональное применение в пределах реально имеющихся полномочий и доказательств. Регуляторы и плательщики задают стимулы и минимальный уровень доказательств. Пациент может задавать предпочтения и исправлять сведения, но не отвечает за поиск дефектов навязанной ему системы.
EU AI Act показывает переход к обязанностям на всём жизненном цикле высокорисковых систем: управление рисками и данными, техническая документация, журналирование, человеческий контроль, точность, устойчивость, кибербезопасность и пострегистрационный мониторинг. Часть ИИ-систем, являющихся медицинскими изделиями или компонентами безопасности и требующих сторонней оценки соответствия, относится к высокому риску; классификацию определяют назначение и применимое продуктовое право, а не маркетинговое слово «ИИ» (Регламент (ЕС) 2024/1689, статья 6 и приложение I; MDCG 2025-6).
Устойчивость — требование к клиническому проектированию
Постоянно обновляемый цифровой пациент расходует не только вычислительные ресурсы. Ему могут требоваться датчики и их замена, сетевой трафик, длительное хранение, дублирующие конвейеры данных, обучение и выполнение моделей, кибербезопасность, специализированные сотрудники и внимание организации. Всё это имеет энергетическую, материальную, финансовую цену и цену упущенных возможностей. В системе с ограниченными ресурсами сложный двойник способен вытеснить более простое наблюдение, персонал или меры доступности, дающие больший эффект для здоровья.
Справедлив и обратный аргумент. Полезная модель может сократить поездки, повторные исследования, неудачные назначения, госпитализации и отходы. «Цифровое» не означает автоматически менее устойчивое, а крупная модель — автоматически неоправданное. Этическое требование состоит в сравнительной оценке жизненного цикла: измерять добавочную клиническую ценность и добавочную нагрузку относительно реалистичных альтернатив, включая распределение пользы и инфраструктурных издержек.
Проспективный кейс 2026 года показывает, почему нужно учитывать и эксплуатацию, и воплощённый в оборудовании след. В оценке жизненного цикла сервиса электронных направлений крупной парижской больницы серверы давали основную часть следа во всех смоделированных режимах использования, а производство вычислительного оборудования составляло 45% углеродного следа и большую часть истощения металлических ресурсов. Работа относится к одному сервису направлений, а не к цифровому двойнику, и не даёт переносимого коэффициента для другой архитектуры. Но она показывает необходимую структуру проспективного учёта: использование, серверы, сеть, терминалы, производство оборудования и сравнение с альтернативой (Morand et al., 2026, PMID 42315963).
Аналитическая записка подразделения по этике Делегации цифрового здравоохранения Министерства здравоохранения Франции от сентября 2025 года относит экологическую ответственность к этике цифровых двойников и предупреждает, что дорогая и энергоёмкая инфраструктура способна углубить неравенство доступа. Это междисциплинарный программный документ, а не рецензируемая оценка жизненного цикла: он ставит вопрос управления, но не вычисляет универсальный след (Digital Twins in Health: Issues, Definitions and Ethical Challenges). Поэтому закупка должна фиксировать частоту обновлений, сроки хранения, срок службы и ремонт устройств, энергопотребление и облачные зависимости, отчётность об углеродном и материальном следе там, где он измерим, непрерывность сервиса и проверку соразмерности: даст ли меньшая и более простая система сопоставимую пользу пациентам?
Пять практических сценариев
1. Дистанционный мониторинг после выписки
Служба помощи при сердечной недостаточности объединяет вес, пульс, симптомы, приём лекарств и пропущенные измерения, чтобы определить очерёдность звонков. Польза — более ранняя реакция без поездок каждого пациента. Риски — ошибка датчика, исключение людей без связи, наблюдение внутри дома и очередь, принимающая отсутствие данных за стабильность.
Минимальные меры: нецифровой маршрут; объявленные часы и сроки ответа; прямое указание, что система не является экстренной службой; рассмотрение пропусков как сигнала безопасности; помощь с устройством; видимое пациенту исправление; измерение нагрузки пациента и близких; ограничение числа учётных записей, устройств и дублирующих уведомлений; регулярное сравнение исходов по доступу, инвалидности, возрасту, полу, языку, этничности и социально-экономическому положению.
2. Предупреждение об ухудшении
Событийная модель обнаруживает паттерн, предшествующий сепсису или повторной госпитализации. Высокая чувствительность может спасать жизнь, но создаёт ложные тревоги; высокая специфичность — пропускает редкие проявления. Этическая единица здесь не площадь под кривой, а весь социотехнический маршрут: кто получит сигнал, что сможет сделать, какую помощь вытеснит и дойдёт ли польза до пациента.
Минимальные меры: проспективный «тихий» тест до включения; заранее заданные правила эскалации и отказа от вывода; оценка времени до действия, нежелательных событий, нагрузки предупреждений, переопределений и исходов; локальная и подгрупповая валидация; контроль дрейфа; ответственный владелец с правом остановки.
3. Двойник для моделирования лечения
Онкологическая или кардиологическая модель сопоставляет вмешательства для одного пациента. Это помогает организовать сложные данные и уменьшить перебор. Но симулированный контрфактический исход особенно легко очеловечить: фраза «двойник ответил» скрывает зависимость от популяционных данных, причинных предпосылок и неизмеренных у конкретного человека параметров.
Минимальные меры: показывать диапазон исходов и предпосылки; отличать прогноз от причинного доказательства; сравнивать со стандартной помощью и междисциплинарным решением; выявлять случаи вне обучающего распределения; не представлять смоделированную пользу как наблюдаемый исход; до автономного управления лечением требовать проспективные клинические доказательства.
4. Цифровое фенотипирование психического здоровья
Телефон использует сон, движение, набор текста, голос или коммуникацию для оценки риска рецидива. Пассивные сигналы способны показать изменение между визитами, в том числе когда его трудно описать. Та же система создаёт непрерывное наблюдение за поведением, выводит интимные сведения о находящихся рядом людях, патологизирует обычные вариации или отменяет рассказ пациента о себе. Этические исследования цифрового фенотипирования выделяют приватность, согласие, смещение, ответственность и риск эпистемической несправедливости (Martinez-Martin et al., 2021, PMID 34319252; Slack & Barclay, 2023, PMID 37725254).
Минимальные меры: добровольное включение, где это возможно; отдельные разрешения для датчиков; локальная обработка на устройстве, где уместно; запрет несвязанных применений в полиции, найме и рекламе; человеческая служба ответа, соответствующая обещанию мониторинга; правило, что модельный вывод начинает разговор, а не отменяет свидетельство пациента.
5. Вторичное использование в исследованиях, страховании и найме
Агрегированные цифровые данные улучшают исследования и выявляют неравенство услуг. Они же могут применяться для сегментации риска, цены, исключения или наблюдения за производительностью. Польза для популяции способна обременить распознаваемую группу даже без раскрытия имён.
Минимальные меры: документированное правовое основание и обоснование общественной пользы; независимая экспертиза; контроль целей и получателей; договорный запрет неблагоприятного неклинического использования; оценка приватности и повторной идентификации; представительство сообществ; публикация значимых результатов и инцидентов; индивидуальный и коллективный механизм возмещения.
От принципов к рабочему договору
Этика внедрения должна отвечать на конкретные вопросы до включения первого пациента или расчёта первого балла.
- Цель: какое точное клиническое или организационное решение система поддерживает, для кого, где и для чего никогда не будет применяться?
- Доказательства: какое сравнение, исходы, внешняя валидация, проспективная оценка и анализ подгрупп подтверждают применение?
- Представление: какие входы наблюдались, сообщены, выведены, смоделированы или отсутствуют? Как показаны источник, время и неопределённость?
- Необходимость: каждая ли собранная и производная переменная нужна и соразмерна цели?
- Выбор: какое уведомление, согласие или иное основание действует? Доступна ли равноценная помощь без необязательного мониторинга?
- Доступ: кто может читать, изменять, экспортировать, обучать на данных или передавать представление и журналируется ли действие?
- Исправление: могут ли пациент и врач исправить первичные данные и оспорить вывод, не уничтожая исторический аудиторский след?
- Человеческие полномочия: кто может поставить вывод под вопрос, переопределить, приостановить или вывести систему из эксплуатации, есть ли у него время и компетенции?
- Отказ: что произойдёт при пропусках, отказе модели от ответа, сбое сети, закрытии поставщика или кибератаке?
- Мониторинг: какие клинические, технические, социальные, нагрузочные и пациентские исходы отслеживаются и какие пороги запускают расследование или остановку?
- Изменение: как валидируются, сообщаются и версионируются новые данные, переобучение, обновление модели, интерфейса и назначения?
- Возмещение и выход: как человек получит объяснение, соответствующее последствиям, запросит ручной пересмотр, обжалует вред, экспортирует важную информацию и выйдет из необязательной программы?
- Устойчивость и соразмерность: каковы энергетические, материальные, кадровые издержки и цена упущенных возможностей на всём жизненном цикле, кто их несёт и даст ли меньшая система сопоставимую пользу?
Эти вопросы соответствуют подходам полного жизненного цикла в руководстве ВОЗ по ИИ для здоровья, NIST AI RMF, управлении рисками медицинских изделий, стандартах безопасной разработки и международных принципах хорошей практики машинного обучения. Они не сводятся к одному сертификату. Ключевые документы: руководство ВОЗ (ISBN 978-92-4-002920-0), NIST AI RMF 1.0, ISO 14971:2019, IEC 62304:2006+A1:2015, IEC 81001-5-1:2021, ISO/IEC 23894:2023, ISO/IEC 42001:2023, ISO 27799:2025, ISO/TS 82304-2:2021 и IMDRF/AIML WG/N88 FINAL:2025.
Чтобы эти тезисы не превратились в ритуальный чек-лист, можно использовать кейс обеспечения доверия: структурированный аргумент, связывающий заявленное свойство — например, безопасность, справедливость или объяснимость — с доказательствами, предпосылками, возражениями, владельцами и пересмотром. Проектный отчёт Института Алана Тьюринга описывает партисипаторную платформу Trustworthy and Ethical Assurance для аргументированного обоснования цифровых двойников (Burr et al., 2024). Это нерецензируемый отчёт о внедрении, а не доказательство клинической пользы; его практическая ценность в том, что обоснование становится проверяемым и пересматриваемым, а не просто заявленным.
Клинические доказательства требуют прозрачной отчётности. CONSORT-AI предлагает указывать назначение, пользователей, место в клиническом маршруте, обработку входов, выходы, взаимодействие человека и ИИ, версии и анализ ошибок (Liu et al., 2020, PMID 32908283). DECIDE-AI охватывает раннюю оценку в живой клинической среде и человеческие факторы (Vasey et al., 2022, PMID 35585198). TRIPOD+AI обновляет правила публикации прогностических моделей (Collins et al., 2024, PMID 38626948). Качественная отчётность делает исследование проверяемым, но сама по себе не доказывает пользу.
Ограничения этического тезиса
Принцип «усиливать врача, а не заменять клиническое решение» задаёт верное направление, но недостаточен.
Некоторые ограниченные автоматические функции могут быть безопаснее обязательной ручной проверки. Человек способен добавить задержку, непоследовательность, предубеждение и ошибку. С другой стороны, номинальная контрольная точка с участием человека может легитимировать опасную рекомендацию. Вопрос не в том, коснулся ли человек результата, а в том, даёт ли связка человека и технологии лучшие, более справедливые и оспоримые исходы для пациентов назначения.
Доказательная база также неоднородна. Значительная часть литературы о цифровых двойниках остаётся концептуальной, технической или ретроспективной; обзор, консенсус, контролируемый эксперимент с датчиком или исследование виньеток могут выявить риск, не доказывая пользу в обычной клинике. Поэтому этическое обеспечение должно сочетаться с проспективной оценкой исходов и реальной способностью организации остановить, исправить или вывести систему из эксплуатации.
Не каждая система цифрового пациента является медицинским изделием, не каждая модель использует ИИ и не каждая этическая обязанность закреплена как юридическое право. Регулирование зависит от юрисдикции и назначения. Прототип, консенсус, стандарт, регуляторное разрешение и патент — разные виды свидетельств. Ни один из них сам по себе не доказывает улучшение исходов в обычной практике.
Наконец, модель не исчерпывает человека. Пациент может изменить цель, отказаться от оптимизации, объяснить аномалию или ценить исход, которого не было в обучающих данных. Этика цифровой медицины начинается там, где избыток человека над профилем считается не шумом, а причиной существования системы.
Вывод
Цифровой пациент должен быть пересматриваемым клиническим инструментом, а не административной судьбой. Он должен показывать неопределённость, отделять факты от выводов, сохранять реальные альтернативы и оставлять прослеживаемый путь от данных к действию. Польза должна быть доказана в тех популяциях и процессах, где система применяется; ошибки — измеримы; владельцы и операторы — подотчётны; человек — способен понять последствия, исправить запись, оспорить решение и выйти из необязательного наблюдения.
Поэтому правило сильнее формулы «оставить врача в контуре»: цифровое представление должно оставаться подчинённым правам, свидетельству, благополучию и меняющимся целям человека.
References / Список литературы
The bibliography is maintained separately from both language versions so that identifiers, source type, evidentiary role, and caveats can be checked without duplicating entries. Peer-reviewed literature is separated from official law and standards; selected implementation reports are labeled non-peer-reviewed; patents are listed independently because a patent is evidence of a technical claim, not of clinical effectiveness.
Peer-reviewed publications and consensus/reporting papers
- Bruynseels K, Santoni de Sio F, van den Hoven J. Digital Twins in Health Care: Ethical Implications of an Emerging Engineering Paradigm. Frontiers in Genetics. 2018;9:31. DOI 10.3389/fgene.2018.00031. PMID 29487613; PMCID PMC5816748. Foundational ethics paper: privacy, inequality, segmentation, therapy/enhancement, value-sensitive design.
- Huang P-H, Kim K-H, Schermer M. Ethical Issues of Digital Twins for Personalized Health Care Service: Preliminary Mapping Study. Journal of Medical Internet Research. 2022;24(1):e33081. DOI 10.2196/33081. PMID 35099399; PMCID PMC8844982. Process-oriented ethical map and working definition.
- Venkatesh KP, Raza MM, Kvedar JC. Health digital twins as tools for precision medicine: Considerations for computation, implementation, and regulation. npj Digital Medicine. 2022;5:150. DOI 10.1038/s41746-022-00694-7. PMID 36138125; PMCID PMC9500019. Definition, implementation, governance, product oversight.
- Laubenbacher R, Mehrad B, Shmulevich I, Trayanova N. Digital twins in medicine. Nature Computational Science. 2024;4:184–191. DOI 10.1038/s43588-024-00607-6. PMID 38532133; PMCID PMC11102043. State-of-the-art review and calibration concept.
- Iqbal JD et al. A consensus statement on the use of digital twins in medicine. npj Digital Medicine. 2025. DOI 10.1038/s41746-025-01897-4. PMID 40721854; PMCID PMC12304465. Participatory expert process with patient-consumer focus group and population survey.
- Obermeyer Z, Powers B, Vogeli C, Mullainathan S. Dissecting racial bias in an algorithm used to manage the health of populations. Science. 2019;366:447–453. DOI 10.1126/science.aax2342. PMID 31649194. Primary empirical evidence on proxy-target bias.
- Dockès J, Varoquaux G, Poline J-B. Preventing dataset shift from breaking machine-learning biomarkers. GigaScience. 2021;10:giab055. DOI 10.1093/gigascience/giab055. PMID 34585237; PMCID PMC8478611.
- Ghassemi M, Oakden-Rayner L, Beam AL. The false hope of current approaches to explainable artificial intelligence in health care. Lancet Digital Health. 2021;3:e745–e750. DOI 10.1016/S2589-7500(21)00208-9. PMID 34711379.
- Goddard K, Roudsari A, Wyatt JC. Automation bias: a systematic review of frequency, effect mediators, and mitigators. Journal of the American Medical Informatics Association. 2012;19:121–127. DOI 10.1136/amiajnl-2011-000089. PMID 21685142; PMCID PMC3240751.
- Lyell D, Coiera E. Automation bias and verification complexity: a systematic review. Journal of the American Medical Informatics Association. 2017;24:423–431. DOI 10.1093/jamia/ocw105. PMID 27516495; PMCID PMC7651899.
- Wiens J et al. Do no harm: a roadmap for responsible machine learning for health care. Nature Medicine. 2019;25:1337–1340. DOI 10.1038/s41591-019-0548-6. PMID 31427808.
- Char DS, Shah NH, Magnus D. Implementing Machine Learning in Health Care—Addressing Ethical Challenges. New England Journal of Medicine. 2018;378:981–983. DOI 10.1056/NEJMp1714229.
- Park HJ. Patient perspectives on informed consent for medical AI: A web-based experiment. Digital Health. 2024;10. DOI 10.1177/20552076241247938. PMID 38698829; PMCID PMC11064747. Empirical survey experiment (South Korea, n=1,000); generalizability is limited.
- Spencer K et al. Patient Perspectives on Sharing Anonymized Personal Health Data Using a Digital System for Dynamic Consent and Research Feedback: A Qualitative Study. Journal of Medical Internet Research. 2016;18:e66. DOI 10.2196/jmir.5011. PMID 27083521; PMCID PMC4851723.
- Martinez-Martin N, Greely HT, Cho MK. Ethical Development of Digital Phenotyping Tools for Mental Health Applications: Delphi Study. JMIR mHealth and uHealth. 2021;9:e27343. DOI 10.2196/27343. PMID 34319252; PMCID PMC8367187.
- Slack SK, Barclay L. First-person disavowals of digital phenotyping and epistemic injustice in psychiatry. Medicine, Health Care and Philosophy. 2023;26:605–614. DOI 10.1007/s11019-023-10174-8. PMID 37725254; PMCID PMC10725846.
- Liu X et al. Reporting guidelines for clinical trial reports for interventions involving artificial intelligence: the CONSORT-AI extension. Nature Medicine. 2020;26:1364–1374. DOI 10.1038/s41591-020-1034-x. PMID 32908283; PMCID PMC7598943.
- Cruz Rivera S et al. Guidelines for clinical trial protocols for interventions involving artificial intelligence: the SPIRIT-AI extension. Nature Medicine. 2020;26:1351–1363. DOI 10.1038/s41591-020-1037-7. PMID 32908284; PMCID PMC7598944.
- Vasey B et al. Reporting guideline for the early-stage clinical evaluation of decision support systems driven by artificial intelligence: DECIDE-AI. Nature Medicine. 2022;28:924–933. DOI 10.1038/s41591-022-01772-9. PMID 35585198.
- Collins GS et al. TRIPOD+AI statement: updated guidance for reporting clinical prediction models that use regression or machine learning methods. BMJ. 2024;385:e078378. DOI 10.1136/bmj-2023-078378. PMID 38626948.
- El Emam K, Jonker E, Arbuckle L, Malin B. A systematic review of re-identification attacks on health data. PLOS ONE. 2011;6:e28071. DOI 10.1371/journal.pone.0028071. PMID 22164229; PMCID PMC3229505.
- Burr CD, Qian S, Winter P, Chico T, Rangel Smith C, Wagg D, Niederer SA. Realising the digital twin: a thematic review and analysis of the ethical, legal, and social issues for digital twins in healthcare. AI & Society. 2026;41(5):5243–5267. DOI 10.1007/s00146-025-02833-6. PMID 42254856; PMCID PMC13241403. Thematic analysis of 29 papers mapped to NASSS; the authors note search and disciplinary-selection limitations.
- Jabbour S, Fouhey D, Shepard S, et al. Measuring the Impact of AI in the Diagnosis of Hospitalized Patients: A Randomized Clinical Vignette Survey Study. JAMA. 2023;330(23):2275–2284. DOI 10.1001/jama.2023.22295. PMID 38112814; PMCID PMC10731487; ClinicalTrials.gov NCT06098950. Standard AI helped, systematically biased AI harmed, and tested image explanations did not significantly remove the harm; simulated vignette design limits inference to live care.
- Gudelunas MK, Lipnick M, Hendrickson C, et al. Low Perfusion and Missed Diagnosis of Hypoxemia by Pulse Oximetry in Darkly Pigmented Skin: A Prospective Study. Anesthesia & Analgesia. 2024;138(3):552–561. DOI 10.1213/ANE.0000000000006755. PMID 38109495. Controlled study of 146 healthy volunteers and 9,763 matched readings; relevant to measurement-layer bias, with limited direct generalizability to clinical monitoring populations.
- Phi NTT, Montori VM, Kunneman M, Ravaud P, Tran V-T. Cumulative Burden of Digital Health Technologies for Patients With Multimorbidity: A Systematic Review. JAMA Network Open. 2025;8(4):e257288. DOI 10.1001/jamanetworkopen.2025.7288. PMID 40279126; PMCID PMC12032558. Modeled technology burden for a hypothetical patient with five chronic conditions; it does not measure real-world use or outcomes.
- Morand C, Névéol A, Tsopra R, et al. Prospectively evaluating the environmental impacts of digital health applications: a case study and recommendations. Journal of the American Medical Informatics Association. Published online 19 June 2026:ocag091. DOI 10.1093/jamia/ocag091. PMID 42315963. Prospective lifecycle case study of one hospital e-referral service; informative for methods, not a digital-twin-specific footprint estimate.
Official law, guidance, and standards
- World Health Organization. Ethics and governance of artificial intelligence for health. 2021. Official publication. ISBN 978-92-4-002920-0. Six principles: autonomy; well-being/safety/public interest; transparency; accountability; inclusiveness/equity; responsiveness/sustainability.
- European Union. Regulation (EU) 2016/679 (GDPR). Official EUR-Lex text. Use the actual jurisdiction and current consolidated text in legal review.
- European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official EUR-Lex text. Applicability is phased; classification and duties are use-specific.
- Medical Device Coordination Group. MDCG 2025-6: FAQ on the interplay between MDR/IVDR and the AI Act. European Commission source. Guidance is not itself binding EU legislation.
- IMDRF. Good machine learning practice for medical device development: Guiding principles. IMDRF/AIML WG/N88 FINAL:2025. Official document page.
- US FDA. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. Final guidance, docket FDA-2022-D-2628. Official guidance page. Useful for planned model changes; FDA guidance is jurisdiction-specific and does not establish general ethical sufficiency.
- NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, 2023. DOI 10.6028/NIST.AI.100-1. Voluntary and cross-sectoral; NIST states that revision is underway.
- ISO. ISO 14971:2019, Medical devices—Application of risk management to medical devices. Official catalogue. Full normative text is paywalled.
- IEC. IEC 62304:2006+A1:2015, Medical device software—Software life cycle processes. Official catalogue. Full normative text is paywalled.
- IEC. IEC 81001-5-1:2021, Health software and health IT systems safety, effectiveness and security—Security activities in the product life cycle. Official catalogue. Full normative text is paywalled.
- ISO/IEC. ISO/IEC 42001:2023, Artificial intelligence—Management system. Official catalogue. Organizational management-system standard, not proof that one clinical model is safe.
- ISO. ISO/TS 82304-2:2021, Health and wellness apps—Quality and reliability. Official catalogue. Technical specification for app quality and labeling.
- HL7. FHIR Release 5. Official specification, including Consent, Provenance, and AuditEvent. Interoperability resources enable implementation; they do not create consent or lawful authority by themselves.
- World Health Organization Regional Office for Europe. Health data governance in the age of artificial intelligence: policy imperatives for the WHO European Region. 2025. Official publication. Reference WHO/EURO:2025-11462-51234-78079. Regional policy brief, not binding law.
- ISO/IEC. ISO/IEC 23894:2023, Information technology—Artificial intelligence—Guidance on risk management. Official catalogue. General AI risk-management guidance; it can complement but does not replace medical-device or clinical risk management.
- ISO. ISO 27799:2025, Health informatics—Information security controls in health based on ISO/IEC 27002. Official catalogue. Edition 3, published December 2025; includes EHRs, health software, medical devices, cloud, and remote or virtual care. Full normative text is paywalled.
Selected thematic and implementation materials (non-peer-reviewed)
- French Ministry of Health, Digital Health Delegation, Ethics Unit. Digital Twins in Health: Issues, Definitions and Ethical Challenges. Briefing note for working group GT15, September 2025. Official PDF. Multidisciplinary policy note with patient representation; useful for representation-versus-replica, distributed responsibility, determinism, access, and environmental sustainability. It is not an empirical lifecycle assessment or settled legal guidance.
- Burr C, Anderson J, Arana S, et al. Trustworthy and Ethical Assurance of Digital Twins: Putting the Gemini Principles into Practice. Alan Turing Institute project report/preprint, 2 December 2024. DOI 10.5281/zenodo.14216049. Describes a participatory, argument-based assurance platform; not peer-reviewed and not evidence of clinical effectiveness.
Relevant patent documents
Patent documents show technical and commercial claims, not clinical validity, ethical acceptability, freedom to operate, or product availability. Status below was checked on 29 July 2026 against the linked record and must be rechecked in the official register before publication.
- US 12,367,985 B2, “Digital twin of a person.” Koninklijke Philips N.V.; granted 22 July 2025; Google Patents lists it as active. The claims concern building and updating a personalized model of anatomy/physical condition from individual and population data for prediction and monitoring. Patent record. This is the strongest granted-patent example in the set, but grant says nothing about clinical utility.
- US 2025/0006367 A1, “Synthetic digital twin for a patient.” IBM; published application, 2 January 2025; listed as pending. It describes a GAN generating disease-specific synthetic time-series data from episodic measurements. Patent record. Ethically relevant to the distinction between a patient-specific model and synthetic data that simulate a member of a cohort.
- US 2019/0005200 A1, “Methods and systems for generating a patient digital twin.” General Electric; published 3 January 2019; US application listed as abandoned. It describes a data structure combining medical records, images, genetics, and history for query, simulation, and recommendations. Patent record. Family members and their status must be checked separately.
- US 2021/0202107 A1, “Healthcare management using digital twins.” HC1; published 1 July 2021; US application listed as abandoned. Claims included individual and population twins, social determinants, future-state simulations, IoT updates, and return-on-investment metrics. Patent record. It is useful ethically because it makes explicit how a clinical representation can be joined to population segmentation and financial objectives.
- US 2026/0124377 A1, “Longitudinal health outcome monitoring using an intelligent injection device platform.” Datadose LLC; published application, 7 May 2026; Google Patents lists it as pending. The claims combine wireless medication-administration records, biomarker collection, adherence/compliance scoring, population analytics, outcome prediction, and device actuation; the description also discusses patient/device digital twins and payer parameters. Patent record. It is ethically relevant to surveillance, contested “compliance” labels, population reuse, and the boundary between recommendation and physical control; the USPTO file and claim status require rechecking.